Hades is a name used in multiple, conflicting cybersecurity contexts, but the supplied facts most directly support Hades as a Russia-nexus ransomware actor and intrusion cluster. It has been identified as one of the ransomware groups that obtained victim access through SocGholish/FakeUpdates infections, indicating use of brokered or malware-enabled initial access prior to ransomware deployment. Separate reporting in the supplied facts also uses Hades as the label for a supply-chain malware cluster associated with malicious npm and PyPI artifacts whose payloads steal secrets from developer workstations and CI/CD environments, including cloud, package-registry, container, and source-code access material. Additional references associate Hades with Russia-linked intrusion activity and “hack-and-leak” style operations, and some reporting discusses possible overlap or confusion with Sofacy-related activity, but those links are not sufficiently consistent to treat all Hades references as a single well-resolved actor. Based on the directly supported facts, Hades should be treated as a Russia-linked threat designation that has been used for ransomware-enabled intrusion activity and for malware operations involving credential and secret theft from software-development environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
A payload associated with the reported worm activity, protected by anti-analysis prompt-injection style comments intended to disrupt AI-assisted malware scanning.
Threat cluster in the Shai-Hulud supply chain campaign associated with payloads that steal secrets from developer workstations and CI/CD environments.
Referenced as a Russia-nexus intrusion set previously associated with hack-and-leak campaigns between 2015 and 2019.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.